Troubleshooting Asymmetric Routing
4 articles
Browse articlesAZTCOFW / DOCUMENTATION
Configuration guides, troubleshooting and practical advice for AZTCOFW.
4 articles
Browse articles9 articles
Browse articles2 articles
Browse articles5 articles
Browse articles3 articles
Browse articles16 articles
Browse articles4 articles
Browse articles3 articles
Browse articles3 articles
Browse articles7 articles
Browse articles4 articles
Browse articles4 articles
Browse articles9 articles
Browse articles4 articles
Browse articles8 articles
Browse articles7 articles
Browse articles1 articles
Browse articles3 articles
Browse articles7 articles
Browse articles14 articles
Browse articles3 articles
Browse articles3 articles
Browse articles2 articles
Browse articles1 articles
Browse articles4 articles
Browse articles5 articles
Browse articles11 articles
Browse articles6 articles
Browse articlesIf the traffic shaping wizard was run previously before an increase in upstream bandwidth, the old limits may still be in effect. Visit Firewall > Traffic Shaper and check the root interface queues, and qInternet queues
If 1:1 NAT (or even Outbound NAT) is properly configured, but the system still appears to access sites like https: //www.netgate.com/ip and http://www.ipchicken.com from main WAN IP Address on the AZTCO-FW firewall, then
In rare edge cases it is possible for the pkg database in /var/db/pkg/ to become corrupted. In the unlikely event this happens to a firewall, it can usually be corrected by running a few commands to re-create the databas
AZTCO-FW log entries may appear in the system log showing something similar to the following: AZTCO-FW kernel: arp: 192.168.1.50 moved from c4 :0c:5c:69:6c:05 to 62:1e:3e:43:04:0c ˓→ on em1 can happen for several reasons
Asymmetric routing happens when traffic between two nodes takes a different path in each direction (e.g. A->B->C, C->D->A), it can be a problem for TCP which has strict state tracking but often does not affect “stateless
Testing authentication servers is possible using the tool located at Diagnostics > Authentication . From that page, testing a user is simple: Navigate to Diagnostics > Authentication Select an Authentication Server Enter
Sometimes log entries will be present that, while labeled with the “Default deny” rule, look like they belong to legitimate traffic. The most common example is seeing a connection blocked involving a web server. This is
This section contains troubleshooting tips for the most common problem with captive portal.
An IPv6 WAN configured to obtain is address via DHCPv6 can suddenly find itself without an IPv6 address if the transaction ID for the IPv6 DHCP client does not match. dhcp6c[xxxxx]: client6_recvadvert: XID mismatch When
Inside the WebGUI, navigate to Diagnostics > Ping and enter in the ISP gateway address. The gateway address is listed on Status > Interfaces for the WAN interface and under Status > Gateways . If the gateway is unknown,
Inside the WebGUI, navigate to Diagnostics > Ping and enter in the ISP gateway address. The gateway address is listed on Status > Interfaces for the WAN interface and under Status > Gateways . If the gateway is unknown,
This section provides guidance for troubleshooting issues with firewall rules.
In AZTCO-FW software versions 2.0.x and 2.1.x, the FTP proxy is in -kernel. The only options to control its behavior are an on/off switch and a list of ports to be used by the proxy. In AZTCO-FW software version 2.2.x an
In some cases, the dpinger gateway monitoring daemon will output numeric error codes in the Gateways log indicating a problem reaching the monitored target IP address. The errors on this page are the most common.
If the WebGUI is not accessible from the LAN, the first thing to check is cabling. If the cable is a hand-made cable or shorter than 3 feet/1 meter, try a different cable. If the client PC is directly connected to a netw
High availability configurations can be complex, and with so many different ways to configure a failover cluster, it can be tricky to get things working properly. In this section, some common (and not so common) problems
The system time on both cluster nodes must be within 90 seconds of each other. Otherwise the time difference is too large and the DHCP daemon processes will not communicate. The interfaces must be assigned identically on
First, open a shell from SSH or the serial/VGA console (option 8). Typically one of these commands will include some obvious consumer of large amounts of system resources. For example, if the system CPU usage is high, it
The vast majority of the time, installations of AZTCO-FW software finish with no problems. The following sections describe the most common problems and the steps to resolve them. See also: Troubleshooting Boot Issues
Due to the finicky nature of IPsec, it isn’t unusual for trouble to arise. Thankfully there are some basic (and some not so basic) troubleshooting steps that can be employed to track down potential problems.
This section covers troubleshooting steps for the most common problems users encounter with L2TP.
If there are issues with traffic being lost, or packets that seem to disappear or never show up (or leave) an interface, try disabling Checksum Offloading as follows: Navigate to System > Advanced on the Networking tab C
This section describes some of the most common problems with multi-WAN and how to troubleshoot them.
NAT can be a complex animal and in all but the most basic environments there are bound to be issues obtaining a good working configuration. This section will go over a few common problems and suggestions on how they can